VERITY / SECURITY EVIDENCE CONTROL

Operational security posture, measured from evidence.

Read the estate you already run. Score the standards you are held to. Expose failed sources, stale readings and unassessed controls before they reach the board.

Run an evidence review

READ-ONLY WHERE SUPPORTED
DEPLOYMENT: ONE AFTERNOON

SOURCESRead-only MEASURESDefined registry STANDARDSJudged natively SYNC06:00 daily
ORG:NORTHWIND_INDVIEW:POSTURELIVE
The Verity security overview showing the current posture score and NIST function scores.
POSTURE42 / 100
CONFIDENCEVery low
SOURCES2 failing
CRITICAL12

Built for security leaders and service providers who have to explain risk clearly, act on it, and prove the work was done.

CISOSecurity teamMSP / MSSPBoard & audit

01 / EVIDENCE

A posture score is only useful when the evidence survives scrutiny.

Verity keeps the source, age and coverage of every measure attached to the result. A missing reading stays missing. A failed connector stays visible. Your team can explain the number without rebuilding it in a spreadsheet.

STATESOURCE CONDITIONSYSTEM RESPONSERISK EFFECT
MEASUREDCurrent reading and healthy sourceAttach source, timestamp and control mappingIncluded in posture
MISSINGNo evidence for an expected controlKeep the control unassessed and visibleScores zero
STALEReading aged or connector stoppedShow age and last successful collectionConfidence reduced

02 / WORKFLOW

One evidence base. Four useful outcomes.

Connect each source once. Verity normalises the evidence and carries it through to reporting, readiness and remediation.

  1. 01Collect

    Read your security tools, documents and passive checks.

  2. 02Measure

    Map the evidence to a defined registry of security measures.

  3. 03Assess

    Score posture and readiness using versioned rules.

  4. 04Act

    Prioritise findings and publish the right report for each audience.

THE PRODUCT, IN USE

Move from evidence to action without losing the source trail.

Each view is a real Verity screen using sanitised demonstration data.

OBSERVE

Establish what the estate can prove.

Start with source health and scope. Verity shows what reported, what stopped and which assets are actually inside the assessment boundary.

The Verity source health screen showing connector status and recent synchronisation.
Source healthEvery connector, its current state and the last successful collection.
The Verity domain register showing discovered assets and evidence sources.
Assessment scopeDiscovered, included and excluded domains stay explicit.

ASSESS

Read the position, and the pressure behind it.

Live findings show where risk is accumulating. Readiness separates assessed controls from unanswered questions. The executive view turns both into a position the board can use.

The Verity findings screen with severity, ageing and owner information.
FindingsSeverity, age, ownership and control impact.
The Verity certification readiness screen showing measured and unmeasured controls.
ReadinessMeasured controls, and the questions still unanswered.
The Verity executive summary with posture, trend and board decisions.
Executive positionThe current position, what moved, and the decisions required.

ACT

Interrogate the evidence, then test the next move.

Ask an operational question and inspect the rows behind the answer. Then run the real scoring model against proposed work, before the team commits effort to it.

The Verity analyst question screen with the evidence rows behind an answer.
Ask VerityThe source rows stay attached to every answer.
The Verity simulation screen comparing current and proposed posture scores.
Scenario planningCompare the effect of proposed work before prioritising it.

03 / OPERATIONS

Start with the whole position. Follow any figure back to its source.

The overview gives security leaders a clear reading of posture, confidence and movement. Analysts can move directly from a score to the measure, finding and source record behind it.

  • Defined measures with history and ownership
  • Source health and last successful sync in view
  • Findings linked to the controls they affect
See how the evidence model works
The Verity overview with the posture score and NIST function scores.
Security overview

04 / STANDARDS

Answer the control once. Use the evidence wherever it applies.

Verity maps the same underlying evidence into every standard you are held to. Each framework keeps its own judgement model, ruleset and reporting language.

Review standards coverage
NIST CSF 2.00–100 posture score
ISO 27001Clauses and Annex A
Cyber EssentialsPass, fail or unproven
Cyber Essentials PlusVerified activities
CIS Controls v8.1Implementation groups
And more…Added as clients are held to them
The Verity standards hub showing current status across the frameworks in scope.
Standards hub

05 / THIRD PARTIES

A blank row on a supplier register is not evidence that anybody has looked.

Verity rates a supplier on what they publish rather than on how they describe themselves: mail authentication, transport, response headers, DNS controls and the front page any visitor sees. A source that answered and found nothing is a result. A source that did not answer is not.

  • Vulnerabilities published against their addresses, ordered by what is being exploited now
  • Names published beneath their domain, and other domains carrying their brand
  • Names a stranger could claim, and domains registered to be mistaken for theirs
  • What moved since the last read, limited to decisions somebody made
STATESOURCE CONDITIONSYSTEM RESPONSERATING EFFECT
OBSERVEDA published record the rating coversUnauthenticated, with no port scan and no credential guessCounts towards the rating
DECLAREDTheir own answer to a questionnaireKept as their statement, with the date it came backNever folded into the rating
UNMEASUREDA check that did not completeNamed beside the grade, never assumed a passCosts its full weight
UNEXAMINEDNobody has looked at this supplierListed on the row, supplier by supplierNot rated, never zero
The Verity printable board report, rendered for paper.
Published monthlyWeb, slides and spreadsheet use the same figures.

06 / REPORTING

Give each audience the level of detail it needs.

Board, compliance and security reports are produced from one month's frozen evidence. The executive summary carries the decisions. The appendix carries the source trail.

ExecutivePosition, movement and decisions
ComplianceReadiness, sources and gaps
Security teamMeasures, owners and actions

07 / SERVICE PROVIDERS

A consistent view across every client estate.

Use the same measures and assessment rules across the book, while keeping each organisation's evidence, credentials and reports separate.

  • See where attention is neededCompare client posture and open findings without inventing a portfolio average.
  • Onboard with evidence on day oneThe passive sources can start without client credentials.
  • Keep access scopedRoles and row-level controls separate each client estate.

08 / SECURITY

Designed to observe your controls, not operate them.

The Verity change log, listing every movement on the findings register with its severity and the time it was recorded.
Every movement, with the time it was seen

Verity requests the narrowest useful permissions and uses read-only access wherever the vendor provides it. Credentials are encrypted per organisation, and one client's sources remain isolated from another's.

Read-only connector scopes Credentials encrypted per organisation Row-level tenant isolation Visible audit and source history
Read the security detail

SEE IT WITH YOUR OWN EVIDENCE

Know where you stand before the next board or audit asks.

Connect one source and review what Verity can measure, what it cannot, and what should happen next.

Request a working session